We run the entire Spotlight Network from a single Google Workspace. Here is exactly how the plumbing works, what it costs, and the three limits that are not in the brochure — including a ceiling of 20 that stops a lot of people cold.
Every few weeks someone asks us the same question. You have a dozen industry sites — HVAC, roofing, law firms, landscaping, athletes — so do you pay for a dozen Google Workspace accounts?
No. We pay for one. And the mechanism that makes that possible is a user alias domain, which is free, widely misunderstood, and carries a hard limit almost nobody discovers until they hit it.
Here is the whole thing, including the parts that bit us.
What a user alias domain actually does
A user alias domain is a mirror of your entire directory. Not a second office. Not a separate team. A mirror.
When you add roofspotlight.com as an alias of your primary domain, Google does not create one address. It creates an address for every user you have, automatically, at no cost. Mail sent to either address lands in the same inbox.
Three things the brochure leaves out
1. It is a mirror, so you cannot split it
Because every user gets an address at every alias domain, you cannot point info@hvacspotlight.com at one person and info@roofspotlight.com at another. Same local part, same mailbox. Always.
If you need role addresses that reach different people, name them by vertical instead of by function. A group called roof@ reaches the roofing lead; hvac@ reaches someone else. Naming by function — info@, hello@, support@ — collapses them all into one place.
2. Nobody can sign in with an alias address
Google is explicit: users authenticate with their primary address only. Chuck can receive and send as chuck@roofspotlight.com forever, but he logs in as chuck@localservicespotlight.com. If your mental model is “each lighthouse gets their own account under their own brand,” alias domains do not deliver that.
3. It is a one-way door
Google does not support migrating a user alias domain into a proper multi-domain setup. If you later decide a vertical needs genuinely separate users, you remove the alias domain and re-add it as a secondary domain — and re-do the mail configuration underneath it. Decide before you build habits on top of it.
The ceiling of 20
This is the limit that surprises people. Google Workspace allows 20 user alias domains per account. Not 20 per user. Twenty, total, forever.
Secondary domains allow 599 — but those bill per user seat, which is the entire thing you were trying to avoid.
Twenty sounds generous right up until you plan a vertical network. Here is our real budget:
Planned network build-out — 7
Remaining headroom — 6
Fourteen of twenty spoken for, and that is before a single acquisition, campaign microsite, or partner brand. The primary domain does not consume a slot, which helps slightly. Six left is not a lot of runway for a network designed to keep adding verticals.
If your network could plausibly exceed twenty brands, decide the architecture before you are at nineteen. The migration path out of alias domains is the one-way door above.
Alias or secondary: the actual decision
User alias domain
- Mirrors your whole directory automatically
- Same people, more brand faces
- No extra seat cost, ever
- Cannot sign in with the alias address
- Cannot split a role address by domain
- No supported migration path out
Secondary domain
- Genuinely separate users per domain
- Different teams, different businesses
- Every user is a paid licence
- Users sign in at their own domain
- Policy differences need org units
- One logo across all domains regardless
The real variable is never how many domains — it is how many humans need a mailbox. Domains are free; people are billed. Four people running thirteen brands costs four seats. Thirteen people running thirteen brands costs thirteen seats no matter how you arrange the domains. Get that number right first and the architecture answers itself.
A bonus lesson we learned the hard way
While auditing our own portfolio for this article we found something worth passing on, because the instinct most people have about it is backwards.
A domain with no MX record cannot receive mail — and that is a clean failure. The sender gets an immediate bounce with a clear error. They know. They pick up the phone instead.
A domain with an MX record but no mailbox behind it is far worse. Mail is accepted, then quietly discarded. Nobody bounces. Nobody knows. Messages simply stop existing.
Our own network, with nothing hidden
We tell clients to audit their domains, so here is ours, unedited. Twelve of our thirteen Spotlight sites currently cannot receive mail. That is deliberate — no mailbox exists yet, so a bounce is the honest answer — and we are working through it in the order below.
| Domain | Inbound mail | SPF | DMARC | Policy |
|---|---|---|---|---|
| localservicespotlight.com | Receiving | OK | OK | p=none |
| hvacspotlight.com | No MX | OK | OK | p=none |
| roofspotlight.com | No MX | OK | OK | p=none |
| lawfirmspotlight.com | No MX | OK | OK | p=none |
| landscaperspotlight.com | No MX | OK | OK | p=none |
| theathletespotlight.com | No MX | OK | OK | p=none |
| dunkerspotlight.com | No MX | OK | OK | p=none |
| pestcontrolspotlight.com | No MX | OK | OK | p=none |
| aibuilderspotlight.com | No MX | OK | OK | p=none |
| concretespotlight.com | No MX | OK | OK | p=none |
| painterspotlight.com | No MX | OK | OK | p=none |
| pressurewashspotlight.com | No MX | OK | OK | p=none |
| dumpsterspotlight.com | No MX | OK | OK | p=none |
Note the last column. Every domain publishes DMARC, which is good, but all of them sit at p=none — a policy that monitors forgery and blocks nothing. Anyone can spoof these domains today and receiving servers will deliver it. Moving to p=quarantine is a bigger security win than any mailbox work, and it is on our list.
Our audit also turned up a domain we used to own and let lapse. It is now held by a reseller and listed for sale. Set auto-renew on everything you would be upset to lose — recovering a lapsed domain costs vastly more than renewing it, if you can recover it at all.
The short version
- Alias domains are free and mirror your whole directory — every user gets an address at every alias domain automatically.
- You get twenty. That is the hard ceiling. Plan the network against it before you are close.
- Nobody signs in with an alias address, and there is no supported path to convert one into a real multi-domain setup later.
- Count people, not domains. Seats are the cost; domains are free.
- Never publish an MX record until a mailbox is actually waiting behind it.
This is the same infrastructure we run for the whole network, documented because we would rather show the wiring than claim it is magic.
